Skip to content

Protocol and Developer Kit

DNSid is two things, and every page in these docs belongs to one of them. Neither needs an account.

LayerWhat it isOpenness
The protocolThe IETF Internet-Draft (draft-ihsanullah-dnsid): the _dnsid TXT record, the two-key model, the lifecycle log, and the verification algorithm. Anyone can implement it independently.Open by definition
The Developer KitThe Go, TypeScript, and Python SDKs, the dnsid CLI with the DNSid Local environment, the cookbook, the conformance suite, and the growing set of integrations. See The Developer Kit.Open source (Apache-2.0); the CLI and DNSid Local ship as free binaries with source coming soon

The relationship between the protocol and the kit is the same as TLS to OpenSSL: the protocol is the contract, the kit is one implementation of it, and anything that follows the contract interoperates.

Verifying a DNSid identity needs nothing but DNS and HTTPS. VerifyDomain resolves the agent’s _dnsid TXT record, fetches the JWKS the operator hosts, checks the status URL the operator controls, and validates the lifecycle log the record points to. No central service is in the loop, and no account is required—any relying party on the internet can verify any DNSid identity.

That’s deliberate: the protocol is explicitly designed to avoid a centralized registry that verifiers must trust to be honest and available.

A DNSid identity is self-managed: you own the domain, sign your own record with your entity key, and host your own JWKS and status endpoints. Pure protocol, no account. See Publish self-managed records. During development, DNSid Local stands in for your DNS and hosting with a disposable network on your machine, and the same SDK code runs in both places.